CVE-2026-68360

UnknownEPSS 0.22%

Last modified

CVE-2026-68360 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().. EPSS estimates a 0.22% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().

Metrics

EPSS Probability
0.22%

13.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 3df2b67793babbea7951b5f601d6df891c63b5d8; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 5e07f292ab5591bf4f588aa7abd22ec86c25d076; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 6c5f31fdf28455a7fd573bda452c80b7b6700247; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 0975c42ed2a3bf32125a920e5d19194289126210; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < c7757db58957ac20cdec6ce575dbd44a6375664e; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 56d2deb6448378118dbe68c4fbb3fbae5f65b18c; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 1a634f464d6153dfa4d7e73a3d78236b65a64ee9; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 94c87871b051d7ad758828a805215a2ec194512a
LinuxLinux5.9

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68360?
In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().
How severe is CVE-2026-68360?
Severity scoring for CVE-2026-68360 is pending analysis. The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2026-68360?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68360?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST